fix: harden thothctl Windows safe I/O
This commit is contained in:
@@ -10,11 +10,15 @@ import (
|
||||
"golang.org/x/sys/windows"
|
||||
)
|
||||
|
||||
const windowsRetainedHandleShareMode uint32 = windows.FILE_SHARE_READ | windows.FILE_SHARE_WRITE
|
||||
|
||||
// ReadCanonicalRegular opens each component with FILE_FLAG_OPEN_REPARSE_POINT and rejects a
|
||||
// reparse point on the opened handle before opening the next component. Windows' Win32 API does
|
||||
// not expose a portable descriptor-relative equivalent of POSIX openat, so a hostile local actor
|
||||
// with permission to rename a normal parent between these opens remains outside this guarantee.
|
||||
// Installation directories therefore need trusted local filesystem/ACL ownership on Windows.
|
||||
// reparse point on the opened handle before opening the next component. Retained handles allow
|
||||
// ordinary read/write sharing but deny delete sharing, which blocks rename or deletion after a
|
||||
// component is opened and throughout the final read. Windows' Win32 API does not expose a
|
||||
// portable descriptor-relative equivalent of POSIX openat, so a hostile local actor can still
|
||||
// replace a not-yet-opened normal component between absolute-path opens. Installation directories
|
||||
// therefore need trusted local filesystem/ACL ownership on Windows.
|
||||
func ReadCanonicalRegular(path string, maximum int64) ([]byte, error) {
|
||||
if err := ValidateCanonicalPath(path); err != nil {
|
||||
return nil, err
|
||||
@@ -62,7 +66,7 @@ func openWindowsComponent(path string, directory bool) (windows.Handle, error) {
|
||||
handle, err := windows.CreateFile(
|
||||
windows.StringToUTF16Ptr(path),
|
||||
windows.GENERIC_READ,
|
||||
windows.FILE_SHARE_READ|windows.FILE_SHARE_WRITE|windows.FILE_SHARE_DELETE,
|
||||
windowsRetainedHandleShareMode,
|
||||
nil,
|
||||
windows.OPEN_EXISTING,
|
||||
flags,
|
||||
|
||||
Reference in New Issue
Block a user